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Monge, Elaine (SCA) 


From: 


pcurtis@chincurtis.com <norep!y+c0a2fdc814f89fb9@formstack.com> 

Sent: 


Friday, July 15, 2016 6:24 PM 

To: 


Breaches, Data (SCA) 

Subject: 


Security Breach Notifications 
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Formstack Submission for form Security Breach Notifications 

Submitted at 07/15/16 6:23 PM 


Business Name: 
Business Address: 

Company Type: 
Your Name: 

Title: 

Contact Address: 


Chin & Curtis, LLP 

75 Federal Street 
Boston, MA 02110 

Other 

Philip Curtis 

Managing Partner 

75 Federal Street 
Boston, MA 02110 


Telephone Number: 

Extension: 

Email Address: 

Relationship to Org: 

Breach Type: 

Date Breach was Discovered: 

Number of Massachusetts Residents 
Affected: 

Person responsible for data breach.: 


(617) 748-5188 

pcurtis@chincurtis.com 

Owner 

Paper 

06/02/2016 

1 

Current Employee 


Please give a detailed explanation of 
how the data breach occurred.: 


We are an immigration law firm and file petitions and applications with 
USCIS that contain individuals’ first and last names and Social 
Security numbers. Upon approval, we send the employee an original 
paper copy of the submission. On June 1, 2016 we prepared an H-1B 
approval package for F. The approval package was sent to her at her 
office address on June 1, however she had not yet begun working. 
The approval package contained F’s first and last names and her 
Social Security number. A mailroom employee looked up F in the 
directory and found another employee with the same name working in 
Cambridge. The mailroom employee then forwarded the package to 
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and realized that the documents were not hers, notified the company 
and forwarded the package to human resources. 

Social Security Numbers = Selection(s) 


Please select the type of personal 
information that was included in the 
breached data.: 


Please check ALL of the boxes that 
apply to your breach.: 


The person(s) with possession of personal information had authorized 
access = Selection(s) 


For breaches involving paper: A lock N/A 
or security mechanism was used to 
physically protect the data.: 

Physical access to systems Yes 

containing personal information was 
restricted to authorized personnel 
only.: 


Network configuration of breached N/A 
system: 

For breaches involving electronic N/A = Selection(s) 
systems, complete the following: 


All Massachusetts residents affected Yes 
by the breach have been notified of 
the breach.: 


Method(s) used to notify 
Massachusetts residents affected by 
the breach (check all that apply):: 


US Mail = Selection(s) 
Other = Selection(s) 


Date notices were first sent to 06/07/2016 

Massachusetts residents 

(MM/DD/YYYY): 

All Massachusetts residents affected Yes 
by the breach have offered 
complimentary credit monitoring 
services .: 


Law enforcement has been notified No 
of this data breach.: 


Please describe how your company 
responded to the breach. Include 
what changes were made or may be 
made to prevent another similar 
breach from occurring.: 


Going forward, we will provide approval packets to employees via 
secure electronic transmission. This will eliminate inadvertently 
sending an approval package to an employee’s work address before 
he or she has commenced employment. Electronic transmission of 
approval packets involves uploading the relevant documents from the 
beneficiary’s electronic file to a secure portal which is then accessed 
by the beneficiary. There is no sending of a paper copy. 
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